{"id":19374,"date":"2022-06-17T10:45:27","date_gmt":"2022-06-17T18:45:27","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/06\/17\/news-13107\/"},"modified":"2022-06-17T10:45:27","modified_gmt":"2022-06-17T18:45:27","slug":"news-13107","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/06\/17\/news-13107\/","title":{"rendered":"Here\u2019s Why You\u2019re Still Stuck in Robocall Hell"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62ab7b8571686457a5be76fb\/master\/pass\/Robocalls-Security-GettyImages-164945796.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Fri, 17 Jun 2022 11:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/lily-hay-newman\">Lily Hay Newman<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">There&#x27;s a good<\/span> reason you&#x27;re still afraid to answer your phone when an unknown number pops up.<\/p>\n<p class=\"paywall\">For years, the telecommunications industry has been trying to curb robocalls, the frustrating and potentially dangerous spam calls that try to scam anyone who picks up the phone. But even after significant milestones in defense\u2014including the <a href=\"https:\/\/www.wired.com\/story\/robocalls-spam-fix-stir-shaken\/\">introduction of two telecom protocols<\/a> that cryptographically authenticate the source of calls\u2014you&#x27;re probably still getting spammy calls that drive you nuts. In spite of the setbacks, though, researchers say they&#x27;ve seen real progress on reducing spam calls in the United States, and there&#x27;s potential for even more improvement.\u00a0<\/p>\n<p class=\"paywall\">At the RSA Conference in San Francisco last week, Josh Bercu of the trade association USTelecom and Gary Warner, director of intelligence at the security firm DarkTower, presented findings on progress squashing robocalls and the illegal call centers they emanate from, which are predominantly located in India. And they dug into the frustrating reality that the issue is far from solved.<\/p>\n<p class=\"paywall\">\u201cI think it\u2019s not going well at all!\u201d Warner tells WIRED. \u201cAnd people understandably wonder why the carriers don\u2019t just block spam calls. But if you&#x27;re AT&amp;T or Verizon or T-Mobile or whoever, it\u2019s not in your purview to decide which conversations people are allowed to have. I don\u2019t think people want to be in that surveillance state where carriers are in a position of deciding what is an acceptable conversation for Americans to have.\u201d<\/p>\n<p class=\"paywall\">That doesn&#x27;t mean the carriers haven&#x27;t stepped up their blocking when they see enough evidence that a call has a suspicious provenance. But USTelecom&#x27;s Bercu notes that deciding how bold to be about blocking is a delicate issue that each phone company handles differently.<\/p>\n<p class=\"paywall\">\u201cAs providers have gotten more aggressive blocking or labeling suspicious calls, they&#x27;ve taken on more risk that they&#x27;ll mis-block or mislabel a legitimate call,\u201d he says. \u201cMaybe it really was a call from the bank or the pharmacy. There is some delicate balancing that providers have to do, and some are more aggressive than others.\u201d<\/p>\n<p class=\"paywall\">Bercu adds, too, that different carriers work with different analytics services to identify suspicious call activity. This can create situations where, as trends in robocalling techniques evolve and spammers use different strategies to bounce calls around international networks, some analytics services may be better at catching certain behavior than others.<\/p>\n<p class=\"paywall\">Bercu is also executive director of the Industry Traceback Group, a neutral entity under USTelecom designated by the Federal Communications Commission to promote intelligence-sharing to trace the source of illegal robocalls and promote collaboration between carriers. The idea is to look at how robocalls circumvent existing technical defenses, identify networks where these protections haven&#x27;t been fully implemented, and work with providers to adopt stronger safeguards.<\/p>\n<p class=\"paywall\">Ultimately, though, DarkTower&#x27;s Warner says that as with other digital criminal industries like email spam, <a href=\"https:\/\/www.wired.com\/story\/business-email-compromise-bec-ransomware-scams\/\">business email compromise<\/a>, and even <a href=\"https:\/\/www.wired.com\/story\/ransomware-revil-blackmatter-surge\/\">ransomware<\/a>, the key to limiting robocalling is to make it more difficult for scammers to operate at every level of their business. This means making it harder for them to route their calls, but also harder to recruit call agents and purchase lead lists\u2014curated collections that claim to contain the phone numbers of targets like elderly people or people with medical issues.\u00a0<\/p>\n<p class=\"paywall\">It also means targeting spammers&#x27; methods for laundering money. The financial sector has already done work in this area by putting flags on potentially suspicious gift cards, but scammers have found ways around this simply by requiring that victims send them a photo of their receipt for the gift card along with the card number itself. This way they can file claims that seem to show that they legitimately purchased and own the gift card. This takes time, though, and scammers have also developed laundering techniques in which they lean on money mule networks in the US or wherever they are operating and have mules open checking accounts where victims can wire money. They then quickly move the money out of the accounts using apps like Zelle, Venmo, or Cash App.<\/p>\n<p class=\"paywall\">\u201cThe key is getting more people to understand the problem who can deny infrastructure to these actors, like communication platforms, financial institutions, telecoms, everyone together,\u201d Warner says. &quot;Denying the ability for criminals to communicate and coordinate\u2014I think that is probably our most actionable path forward.\u201d<\/p>\n<p class=\"paywall\">He adds, too, that while the Indian government has <a href=\"https:\/\/www.wired.com\/story\/india-robocall-spam-caller-id\/\">struggled to meaningfully address<\/a> the issue, Indian law enforcement has significantly ramped up arrests related to illegal call centers. But even arresting more than a dozen people a week won&#x27;t curb the problem when there are estimated to be tens of thousands\u00a0of people working on illegal robocalling scams in India alone.<\/p>\n<p class=\"paywall\">YouMail, the blocking company that has reported estimated robocall volumes in the US for years, found that Americans received just under 4 billion robocalls in May, down from 4.74 billion in May 2019. In general, the company&#x27;s stats underscore both improvement in the total volume of robocalls and the reality that numbers are still extremely high.<\/p>\n<p class=\"paywall\">\u201cThe only way we could ensure that we never get any robocalls ever would be that we don\u2019t have phone calls at all,\u201d USTelecom&#x27;s Bercu says. \u201cWhen you can receive calls, you&#x27;re opening up your network to someone else. So that&#x27;s why I increasingly like to think about the problem the same way you would think about other cybersecurity issues. Every provider needs to do due diligence, and we need accountability\u2014but also collaboration.\u201d<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/how-to-stop-robocalls\/\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62ab7b8571686457a5be76fb\/master\/pass\/Robocalls-Security-GettyImages-164945796.jpg\"\/><\/p>\n<p><strong>Credit to Author: Lily Hay Newman| Date: Fri, 17 Jun 2022 11:00:00 +0000<\/strong><\/p>\n<p>Despite major progress fighting spam and scams, the roots of the problem go far deeper than your phone company\u2019s defenses.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21358],"class_list":["post-19374","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-cyberattacks-and-hacks"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19374","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19374"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19374\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19374"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19374"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19374"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}